Optus 2022: 9.8M Records, One Unauthenticated API, Zero Exploits
Australia's second-largest telco exposed ~9.8M customer records via an API left unauthenticated in production. No zero-day, no phishing — just enumeration.
Australia's second-largest telco exposed ~9.8M customer records via an API left unauthenticated in production. No zero-day, no phishing — just enumeration.
An 18-year-old bought a contractor's Uber password, bombarded them with MFA pushes until one was approved, then roamed to vSphere via hardcoded credentials.
August's 'contained' developer-account compromise returned in December as stolen vault backups. Inside the two-act breach.
A forums database with bcrypt hashes and salts hit a criminal forum. The real blast radius was everywhere else users reused passwords.
Slope's telemetry backend held plaintext seed phrases, and attackers harvested them. The chain saw only valid signatures — and that is the whole lesson.
Fake Okta pages, real-time MFA relay, and one crew harvesting 10,000 identities. Why Cloudflare walked away clean and Twilio didn't.
A routine upgrade left message proofs rubber-stamped. Hundreds of copycats drained the bridge in crypto's most chaotic heist.
A patched OAuth endpoint answered one question too honestly: which phone belongs to which handle. The dataset sold for $30k — the class lesson is still with us.
A criminal franchise paid up to $1M for flaws in its own malware, website, and Tor infrastructure — Silicon Valley tactics inside the ransomware economy.
Furnaces halted, footage released, workers warned. How a state-aligned group turned industrial sabotage into broadcast messaging.
Five thousand cloud VMs, each pushing 5,000 rps of encrypted traffic at one small website. June 2022's record flood and the edge doctrine it sealed.
A 2-of-5 multisig guarding nine figures. Lazarus took the two keys it needed, and the bridge-custody era changed for good.